Fake McAfee Pop-Up: Identify, Remove, and Stop the Scam


XINSTALL BY CLICKING THE DOWNLOAD FILE

For fixing Windows errors, we recommend Fortect:

Fortect will identify and deploy the correct fix for your Windows errors. Follow the 3 easy steps to get rid of Windows errors:

  • Download Fortect and install it on your PC
  • Launch the tool and Start scanning your PC for Windows errors
  • Right-click on Start Repair to deploy the right fix for each error encountered during the scan
Download Now Fortect has been downloaded by 0 readers this month, rated 4.6 on TrustPilot

A fake McAfee pop-up is a webpage, advertisement, browser notification, email, or unwanted application that uses McAfee’s name and branding to frighten you into clicking, calling a telephone number, downloading software, revealing information, or making a payment.

Do not click inside the warning, call its number, install its recommended “fix,” or enter payment information. Close the page using the browser’s real tab or window controls, then investigate where the warning came from.

The alert itself is not proof that your computer or phone is infected. Many fake McAfee warnings are ordinary webpages or website notifications designed to look like security-software alerts. A more serious compromise becomes possible when you download or install something, grant remote access, add a browser extension, or provide credentials or financial information.

The FTC specifically warns that scammers impersonate companies such as McAfee in fake subscription-renewal and technical-support schemes. Genuine security warnings do not instruct you to call a random telephone number displayed in a pop-up.

What to do immediately

  1. Do not click any button inside the warning. That includes “Scan,” “Remove Virus,” “Renew,” “Cancel,” “OK,” and a close button drawn inside the page.
  2. Do not call the displayed telephone number. A telephone number inside a security warning is one of the clearest signs of a technical-support scam.
  3. Close the real browser tab or window. Use the tab’s actual close control or the browser window’s operating-system control. When the page prevents you from closing it, end the browser through Task Manager on Windows or Force Quit on a Mac.
  4. Do not restore the suspicious tab. If the browser asks to reopen the previous session, decline or reopen only the tabs you recognize.
  5. Revoke website notification permissions. This is especially important when alerts appear in a corner of the desktop or continue after you leave the original webpage.
  6. Inspect downloads and browser extensions. Delete an unexpected download without opening it. Remove extensions you do not recognize after confirming they are not required by your employer, school, or legitimate security software.
  7. Run a trusted security scan when warranted. A scan is appropriate when you opened a download, installed an application, added an extension, or continue seeing redirects and advertisements.
  8. Protect your accounts and money if you interacted with the scam. Change exposed passwords, contact your financial institution, and end remote-access sessions immediately.

McAfee advises users not to interact with suspicious pop-up controls and to close the browser through trusted browser or operating-system controls instead. The FTC similarly advises consumers not to call numbers in security warnings and to use independently verified support channels.

Is the McAfee pop-up fake?

The following clues can help you diagnose it.

What you observeWhat it probably means
The warning appears inside a browser tab with an unfamiliar address in the address barIt is probably a scam webpage or redirect
The alert appears in a desktop corner and names Chrome, Edge, Firefox, Safari, or an unfamiliar websiteIt is probably a browser push notification
It claims that several viruses were found after an instant “scan”Treat it as a fake scan animation, not a verified security result
It contains a telephone number you must callTreat it as a technical-support scam
It asks you to install remote-control softwareStop immediately; this is a serious scam indicator
It demands gift cards, cryptocurrency, a wire transfer, or a payment appIt is a scam
It says a subscription renewed but no charge appears in your bank or card accountThe renewal notice is probably fabricated
The message appears inside the independently opened McAfee application and matches your accountIt may be genuine, but verify through the account rather than the alert

The FTC says real security pop-up warnings do not tell users to call a telephone number. It also warns that fake renewal messages frequently impersonate well-known companies and lead victims into remote-access and refund scams.

McAfee recommends independently signing in to the user’s account to check whether a message is genuine. A familiar logo, polished design, correct spelling, or knowledge of your approximate location does not prove that a warning came from McAfee.

A fake alert does not automatically mean you have a virus

Seeing a warning and closing it is different from installing malware.

In many cases, the browser has simply displayed:

  • a fraudulent webpage;
  • a redirect from an advertisement;
  • or a notification from a website that previously received permission to send alerts.

Browser notifications are managed separately from ordinary pop-up windows. Consequently, turning on a pop-up blocker might not stop notifications that a website has already been allowed to send. Firefox, for example, provides separate controls for website notification permissions, while Safari can display authorized website notifications even when Safari itself is not open.

Malware or adware is more plausible when advertisements appear across unrelated sites or applications, the browser’s search engine or homepage changes without permission, unfamiliar extensions keep returning, or an unknown program runs at startup.

Why fake McAfee alerts appear

A website redirected you

A deceptive advertisement, compromised advertising placement, mistyped address, or questionable website can redirect the browser to a page that imitates a virus scan.

The page may display progress bars, fabricated file names, sirens, countdown timers, or statements such as “Your protection has expired.” These are visual elements produced by the webpage; they are not a verified result from your installed security software.

You allowed website notifications

Some websites display a prompt asking you to press Allow to prove you are human, watch a video, download a file, or continue to a page. Pressing Allow may authorize that site to send browser notifications.

The site can then deliver McAfee-branded warnings through the browser’s notification system. The notifications may resemble operating-system alerts because they appear outside the original browser tab.

An extension or application is generating advertisements

A questionable browser extension may inject advertisements, alter search results, open new tabs, or redirect you to scam pages. On Android, a recently installed application may display advertisements over other apps.

You received a fake renewal notice

Fake subscription messages claim that a McAfee product renewed automatically or that a large charge is pending. They normally tell you to call immediately to cancel or obtain a refund.

The scammer may then request remote access, ask you to sign in to online banking, create a false refund error, and demand repayment by gift card, wire transfer, cryptocurrency, or another difficult-to-reverse method.

Diagnose where the alert is coming from

It appears only inside one browser tab

This is probably an in-page scam or redirect.

Close the tab using the browser’s real tab control. Remove data belonging to the offending site if it reopens, and check whether the site has notification permission.

It appears in a corner of the Windows or Mac desktop

Look for the source shown on the notification. It may display:

  • the browser’s name or icon;
  • the website’s domain;
  • or the name of a Safari website or web application.

This usually indicates an allowed website notification, not a normal McAfee application alert.

It appears after you leave the website

The site may have browser notification permission. Removing cookies alone might not revoke that permission; inspect the browser’s notification settings directly.

It appears across unrelated websites

Review extensions, browser startup pages, the default search engine, and recently installed applications. Run a security scan if the behavior continues.

It appears over unrelated Android apps

A recently installed Android application may be displaying advertisements. Review recently installed apps, notification access, accessibility access, and “display over other apps” privileges.

It appears only inside the installed McAfee application

Close the message and independently reopen McAfee from the Start menu, Applications folder, or another trusted shortcut. Review the account or subscription status from there.

It arrived by email or text

Do not call, click, or reply. Independently inspect your bank or card activity and your actual McAfee account. The absence of the claimed charge is strong evidence that a renewal message was fabricated.

How to remove fake McAfee pop-ups

Browser menu wording can vary slightly by operating system and browser release. The paths below reflect official vendor documentation available in July 2026.

Google Chrome on Windows or Mac

1. Remove suspicious notification permissions

  1. Open Chrome.
  2. Select the three-dot menu.
  3. Open Settings.
  4. Select Privacy and security.
  5. Select Site settings.
  6. Select Notifications.
  7. Review websites allowed to send notifications.
  8. Block or remove unfamiliar and untrusted sites.

Google’s current Chrome documentation places notification controls under Settings → Privacy and security → Site settings → Notifications.

2. Block pop-ups and redirects

  1. Remain in Site settings.
  2. Open Pop-ups and redirects.
  3. Select the option that prevents sites from sending pop-ups or using redirects.
  4. Review any sites listed as exceptions.

Chrome manages pop-ups separately from notification permissions, so check both settings.

3. Review extensions

  1. Open the three-dot menu.
  2. Select Extensions.
  3. Select Manage extensions.
  4. Remove extensions you do not recognize or no longer need.

Do not remove a legitimate security or workplace extension solely because its name is unfamiliar. Check its publisher and ask the organization’s IT team when the browser is managed. Google’s official extension controls are available through More → Extensions → Manage extensions.

4. Clear the offending site’s data

Clearing the suspect site’s cookies and cached information may prevent it from reopening with the same stored state. Prefer removing data for the specific site when possible because clearing all cookies signs you out of many websites.

5. Reset Chrome only when necessary

When the homepage, search engine, startup pages, or other browser settings remain altered, open Settings → Reset settings → Restore settings to their original defaults. Treat this as a fallback after removing notification permissions and extensions.

Microsoft Edge

1. Block the website’s notifications

  1. Open Edge.
  2. Open Settings and more.
  3. Select Settings.
  4. Select Privacy, search, and services.
  5. Open Site permissions and then All sites.
  6. Select the suspicious website.
  7. Find Notifications.
  8. Change it to Block.

You can also open the site-information control to the left of the address bar and change that site’s notification permission to Block.

2. Block pop-ups and redirects

Open:

Settings → Privacy, search, and services → Site permissions → All permissions → Pop-ups and redirects

Turn on the Blocked setting.

3. Remove suspicious extensions

Select the Extensions control beside the address bar, open the extension’s menu, and choose Remove from Microsoft Edge.

4. Clear browsing data when needed

Open:

Settings → Privacy, search, and services → Clear browsing data → Choose what to clear

Select an appropriate time range and remove cookies, cached files, or history as necessary. Keep in mind that deleting cookies can sign you out of websites.

Mozilla Firefox

1. Revoke notification permission

  1. Open the Firefox menu.
  2. Select Settings.
  3. Select Privacy & Security.
  4. Scroll to Permissions.
  5. Beside Notifications, select Settings.
  6. Find the suspicious site.
  7. Select Block to stop notifications and future requests, or Remove Website to revoke the current permission while allowing the site to ask again.
  8. Save the changes.

Firefox also provides Remove All Websites, which revokes the listed notification permissions.

2. Review Firefox add-ons

Open the Firefox menu, select Add-ons and themes, and inspect Extensions. Disable or remove add-ons you do not recognize. Mozilla advises removing an extension when you do not remember installing it or cannot establish why it is needed.

3. Confirm pop-up blocking

Firefox has separate controls for pop-up windows. Check the browser’s Privacy & Security settings and review any allowed-site exceptions.

Safari on Mac

1. Deny website notification permission

  1. Open Safari.
  2. Select Safari → Settings.
  3. Select Websites.
  4. Select Notifications.
  5. Deny or remove suspicious websites.
  6. To prevent future requests, deselect Allow websites to ask for permission to send notifications.

Apple documents these controls under Safari’s Websites settings.

2. Turn off the website in macOS Notifications

  1. Open the Apple menu.
  2. Select System Settings.
  3. Select Notifications.
  4. Under Application Notifications, select the website or web app.
  5. Turn off Allow notifications.

Safari-authorized website notifications can appear even when Safari is not open, which explains why some fake alerts seem to come directly from macOS.

3. Block pop-up windows

Open:

Safari → Settings → Websites → Pop-up Windows

Set unfamiliar sites—and the default for other websites—to Block or Block and Notify.

4. Remove website data

Open:

Safari → Settings → Privacy → Manage Website Data

Select the offending site and choose Remove, or use Remove All when broader cleanup is necessary. Removing website data can sign you out and erase saved site preferences.

5. Inspect Safari extensions and applications

Open Safari → Settings → Extensions and uninstall extensions you do not recognize. Apple recommends uninstalling an extension when you cannot determine what it does or no longer need it.

Also review the Applications folder and System Settings → General → Login Items & Extensions for unfamiliar software that launches automatically.

Android

1. Stop Chrome website notifications

In Chrome, open:

More → Settings → Site settings → Notifications

Review allowed sites and block suspicious ones. You can also visit a site, open the site-information control beside the address bar, and change its permissions.

2. Block pop-ups and redirects

Open:

Chrome → More → Settings → Site settings → Pop-ups and redirects

Set the control to blocked.

3. Clear Chrome browsing data

Open:

Chrome → More → Settings → Privacy and security → Delete browsing data

Remove relevant cookies, cached files, and browsing history.

4. Remove problematic applications

When advertisements appear outside Chrome or over unrelated apps, review applications installed shortly before the problem began. Uninstall suspicious apps through Android settings or Google Play. Google’s unwanted-pop-up guidance specifically directs users to remove problematic apps and stop abusive site notifications.

5. Run Google Play Protect

Open the Google Play Store, select your profile, and open Play Protect. Run a scan and keep app scanning enabled. Google Play Protect is designed to check Android applications for potentially harmful behavior.

6. Consider Safe Mode for persistent cross-app ads

When you cannot identify the responsible application, Android Safe Mode can help determine whether a downloaded app is causing the behavior. If the advertisements stop in Safe Mode, uninstall recently downloaded applications one at a time after restarting normally.

iPhone and iPad

1. Close the Safari tab

Do not press buttons drawn inside the page. Close the actual Safari tab or close Safari through the app switcher if the page has taken over the screen.

2. Enable Safari protections

Open:

Settings → Apps → Safari

Turn on:

  • Block Pop-ups
  • Fraudulent Website Warning

Apple recommends both settings when dealing with deceptive pop-ups and fraudulent sites.

3. Clear Safari history or website data

Open:

Settings → Apps → Safari → Clear History and Website Data

For a more targeted website-data cleanup, open:

Settings → Apps → Safari → Advanced → Website Data

Apple’s current instructions place Safari data controls under the Apps section of Settings.

4. Delete an application you installed from the warning

Touch and hold the suspicious application, select Remove App, and then Delete App.

5. Review configuration profiles only when relevant

A normal pop-up cannot silently install a configuration profile. However, check this area if the scam persuaded you to download and approve one:

Settings → General → VPN & Device Management

Remove only profiles you know are unauthorized. Work, school, VPN, and mobile-provider profiles may be legitimate.

6. Check for a spam calendar separately

When the “McAfee alerts” are calendar events rather than browser pages, open Calendar, select Calendars, inspect unfamiliar subscriptions, and choose Unsubscribe or Delete Calendar.

Scan the device safely

Windows 11

Windows includes the Windows Security application and Microsoft Defender Antivirus.

  1. Open the Start menu.
  2. Search for Windows Security.
  3. Select Virus & threat protection.
  4. Run a Quick scan.
  5. When suspicious behavior continues, open Scan options and consider a Full scan.
  6. For a more persistent suspected infection, Microsoft Defender Offline can restart the computer and scan without loading the normal Windows environment.

Microsoft advises running a quick scan when malware is suspected and offers full and offline scans for deeper examination.

Do not install a scanner promoted by the fake pop-up.

Mac

Update macOS and restart the Mac. Review:

  • Applications;
  • Safari and other browser extensions;
  • Login Items & Extensions;
  • unfamiliar device-management profiles;
  • and recently downloaded files.

macOS includes Gatekeeper, notarization checks, and XProtect. XProtect detects and blocks known malicious software and receives security updates automatically, but those built-in protections do not make every download or browser extension trustworthy.

Apple also recommends checking Applications and Safari extensions when persistent pop-ups suggest unwanted software.

Android

Run Google Play Protect, uninstall recently added suspicious applications, and review sensitive app privileges such as:

  • accessibility access;
  • device-administrator access;
  • notification access;
  • installation of unknown apps;
  • and display over other apps.

Persistent advertisements across applications are more suggestive of an installed app than a single browser-page incident.

iPhone and iPad

A webpage claiming to have scanned an iPhone is not, by itself, evidence that the device was actually scanned or infected. Apple characterizes browser warnings about viruses and security problems as typically fraudulent advertisements intended to prompt a download or obtain information or money.

Focus on what happened after the warning:

  • Did you install an app?
  • Did you approve a configuration profile?
  • Did you enter an account password?
  • Did you disclose a verification code?
  • Did you provide payment information?

Update iOS or iPadOS, clear the browser data, remove anything you knowingly installed from the scam, and protect exposed accounts.

What to do based on what happened

I only saw the warning

Close it, remove any notification permission associated with the site, and continue monitoring the device.

A factory reset, card replacement, and mass password change are generally disproportionate when you merely viewed a webpage and did not download, install, call, pay, or enter information.

I clicked a button but nothing appeared to download

Close the page. Inspect the browser’s download list, notification permissions, and extensions. Clear the offending site’s data and run a scan when you are uncertain whether a file opened.

I pressed “Allow” for notifications

Revoke the site’s notification permission in the browser. Blocking ordinary pop-up windows will not necessarily remove an already granted notification permission.

A file downloaded, but I did not open it

Do not open it to inspect it. Delete it, empty the Recycle Bin or Trash, and use your existing security software to scan the Downloads folder or device.

I opened or installed the file

Disconnect from sensitive activities such as banking. Uninstall the application when possible, inspect startup items and extensions, and run a full security scan.

Treat the incident more seriously when the program requested administrator access, accessibility access, device management, screen recording, or permission to control the computer.

I installed a browser extension

Remove or disable it through the browser’s extension manager. Then inspect:

  • homepage and startup-page settings;
  • default search engine;
  • site notification permissions;
  • proxy settings;
  • and synchronized browser profiles.

Change sensitive passwords when the extension had broad permission to read and modify data on websites.

I called the telephone number

End the call. Do not follow further instructions, accept a refund, purchase a gift card, transfer money, or provide a verification code.

The FTC warns that fake renewal and support callers frequently use remote access and fabricated refund errors to obtain money.

I installed remote-access software

Disconnect the affected device from the internet. End any active remote session and shut down the remote-access application.

From a trusted device where possible:

  1. Change the email password.
  2. Change banking and payment passwords.
  3. Replace any reused passwords.
  4. Turn on multifactor authentication.
  5. Contact financial institutions.
  6. Review recent account activity.
  7. Remove the remote-access application.
  8. Scan the affected device before using it for sensitive activity.

McAfee advises disconnecting a device when unauthorized remote access was allowed. The FTC advises updating security software, scanning the device, and removing identified problems after a scammer has had computer access.

I allowed someone to control my computer

Assume that anything visible or accessible during the session may have been viewed.

Check:

  • email forwarding rules;
  • recently installed software;
  • browser extensions;
  • saved passwords;
  • cloud-storage activity;
  • bank transactions;
  • payment-app activity;
  • and new users or startup items.

A qualified technician may be appropriate when you cannot determine what the remote operator installed or changed.

I entered a username and password

Change the password immediately from a trusted device. Start with your email account because access to email can enable password resets elsewhere.

Then:

  1. Replace the password anywhere it was reused.
  2. Sign out other sessions.
  3. Review recovery email addresses and telephone numbers.
  4. Enable multifactor authentication.
  5. Check for unauthorized mailbox-forwarding rules.
  6. Monitor sign-in alerts.

The FTC recommends replacing exposed passwords and changing reused copies of the same password. CISA recommends strong, unique passwords, password managers, and multifactor authentication.

I provided a one-time verification code

Change the account password and review active sessions immediately. Contact the service’s official support team if the attacker may have changed account recovery details.

Never approve an unexpected multifactor prompt or share a verification code with someone claiming to provide technical support.

I entered card or banking information

Contact the bank or card issuer immediately using the number printed on the card, the verified banking application, or a known official statement.

Explain that the information was disclosed to a scammer. Ask the institution to:

  • block or replace the card when appropriate;
  • monitor or restrict the account;
  • dispute unauthorized charges;
  • and advise whether account numbers or online-banking credentials must change.

The FTC recommends contacting the card issuer or bank, reporting the fraudulent transaction, and requesting reversal where possible.

I paid the scammer

Act immediately, even when recovery appears unlikely.

  • Credit or debit card: Contact the issuer and request a fraud review or charge reversal.
  • Bank transfer: Contact the bank and ask whether the transfer can be recalled.
  • Payment app: Report the transaction to the app provider and the linked bank or card issuer.
  • Gift card: Contact the gift-card issuer and preserve the card and receipt.
  • Wire transfer: Contact the transfer company and request reversal.
  • Cryptocurrency: Contact the exchange or service used to send the payment. Cryptocurrency transactions are commonly difficult or impossible to reverse, but reporting them can still be useful.

These are the payment-specific actions recommended by the FTC for scam victims.

I disclosed identity information

For United States readers, the FTC directs people who disclosed a Social Security number or experienced identity theft to use the government’s IdentityTheft recovery process. Readers elsewhere should contact the relevant national identity, credit-reporting, consumer-protection, and law-enforcement bodies.

The device belongs to an employer or school

Disconnect it from sensitive work when appropriate and contact the organization’s IT or security team immediately. Do not remove managed software, delete logs, or reset the device unless instructed. The organization may need evidence for incident response and may have central controls unavailable to the user.

Do you need to factory reset the device?

Usually not.

A factory reset is not the normal first response to a browser notification or a single scam webpage. Begin by closing the page, removing its notification permission, inspecting extensions, uninstalling unwanted software, and scanning the device.

A professional assessment or reset becomes more reasonable when:

  • unknown remote-control tools keep returning;
  • administrator or device-management settings cannot be restored;
  • security software is disabled repeatedly;
  • browser changes return after resets;
  • confirmed malware resists removal;
  • unexplained accounts or startup services appear;
  • or sensitive activity continues after ordinary remediation.

Back up essential personal files carefully before a reset. Do not back up suspicious applications, installers, scripts, or browser extensions.

How to verify a genuine McAfee warning

  1. Close the message.
  2. Do not use its link or telephone number.
  3. Open the installed McAfee application independently.
  4. Sign in through a saved bookmark or an address you type yourself.
  5. Review subscription, billing, device, and protection status.
  6. Contact support through the verified application or account.

McAfee advises customers who are uncertain about a message to sign in to their account and verify it there. It also accepts reports of McAfee brand-impersonation scams at [email protected].

How to prevent another fake antivirus alert

Treat notification requests as security decisions

Do not press Allow merely because a site says it is required to:

  • prove you are human;
  • watch a video;
  • begin a download;
  • dismiss an advertisement;
  • or continue browsing.

Permit notifications only for sites from which you genuinely want recurring alerts.

Review permissions periodically

Inspect the notification list in every browser you use. A permission granted months ago can remain active after you have forgotten the website.

Keep extensions to a minimum

Remove extensions that are unused, abandoned, unfamiliar, or unnecessarily powerful. Prefer extensions from verified developers and review the permissions they request.

Install software through trusted sources

Use official application stores or the developer’s known website. Do not install “updates,” “antivirus,” browser add-ons, or cleanup tools promoted through an unexpected advertisement.

Apple similarly advises obtaining applications through the App Store or directly from a trusted developer rather than through an advertisement or unsolicited link.

Update the operating system and browser

Security updates can improve protection against malicious sites, unwanted software, and browser exploitation. Enable automatic updates where practical.

Use unique passwords and multifactor authentication

A password manager can generate and store unique passwords, limiting the damage if one account is compromised. Multifactor authentication adds another verification step and makes password-only account takeover more difficult.

Establish a family rule for support warnings

A useful rule is:

Never call a telephone number, install remote-access software, or make a payment because a webpage says the device has a virus.

Pause, close the page, and verify the issue independently.

How to report a fake McAfee pop-up

Preserve useful evidence without continuing to interact with the scam. Record or photograph:

  • the displayed website address;
  • the claimed company;
  • the telephone number;
  • the date and time;
  • payment receipts;
  • downloaded filenames;
  • and the name of any remote-access application.

McAfee currently directs users to report fraudulent messages using its brand to [email protected].

United States readers can report technical-support and impersonation scams through the FTC’s ReportFraud service. The FTC says these reports help identify trends and build cases against scammers.

Readers outside the United States should report the incident to the relevant national consumer-protection, cybercrime, financial-fraud, or data-protection authority.

Frequently asked questions

Is the fake McAfee pop-up a virus?

Not necessarily. It may be a scam webpage or a website notification delivered through your browser. Malware becomes more plausible when you installed or opened something, added an extension, granted remote access, or continue seeing advertisements across unrelated sites and applications.

Why am I getting McAfee alerts when I do not have McAfee?

The scammer is using a familiar security brand to make the warning appear credible. The page does not need to know whether you use McAfee.

Why does the alert appear when my browser is closed?

The website may have notification permission. On Mac, authorized Safari website notifications can appear even when Safari is not open. Other browsers may also remain able to deliver site notifications through background browser components or the operating system.

Why did blocking pop-ups not stop it?

Pop-up windows and website notifications are separate browser features. You must revoke the site’s notification permission in addition to enabling the pop-up blocker.

Can clicking the fake X button cause a download?

A close icon drawn inside a webpage can be programmed like any other webpage button. Use the real browser-tab or window control instead. McAfee specifically cautions that deceptive close buttons may trigger redirects or downloads.

Should I call the number in a McAfee warning?

No. The FTC states that real security pop-up warnings do not ask you to call a telephone number. Verify the issue by independently opening the installed security application or account.

How can I verify whether my McAfee subscription renewed?

Sign in to the McAfee account independently and inspect the subscription and billing status. Also review your actual card or bank activity. Do not use a link or number supplied by the message.

Do I need to buy antivirus software because of the warning?

No. A webpage’s demand to buy a product is not a trustworthy security assessment. Use security software already installed on the device or independently research a product through its verified publisher.

Should I change my passwords?

Change them when you entered credentials, shared a verification code, installed a highly privileged extension, or allowed remote access. A password change is generally unnecessary when you only viewed and closed a page.

Should I factory reset my computer or phone?

Usually not for a webpage or notification alone. Consider professional remediation or a reset when unauthorized remote-control tools, administrator changes, or confirmed malware persist after normal cleanup.

Can an iPhone webpage scan the iPhone for viruses?

Treat a webpage claiming to have completed such a scan as fraudulent. Apple advises users not to believe browser pop-ups warning about viruses or security problems and not to follow their links or telephone numbers.

How do I stop fake McAfee alerts in the lower-right corner of Windows?

Identify which browser or website is named in the notification. Open that browser’s notification settings and block the site. In Chrome, use Settings → Privacy and security → Site settings → Notifications. In Edge, open the site under Site permissions → All sites and set Notifications to Block.

What should I do if I paid the scammer?

Contact the payment provider immediately and request fraud review or reversal. Preserve receipts, messages, and transaction details. Then report the incident and protect any accounts or devices the scammer accessed.

How should I help an older relative who encountered the scam?

Avoid blame. Ask exactly what happened:

  • Was anything clicked?
  • Was a number called?
  • Was software installed?
  • Was remote access granted?
  • Were passwords, codes, or payment details disclosed?
  • Was money sent?

Use the answers to select a proportionate response. Sitting with the person while they contact the bank, change passwords, or remove the notification permission is often more effective than simply telling them what to do.

Final takeaway

A fake McAfee pop-up should be handled with three principles:

Close and verify independently. Do not trust the page’s buttons, telephone number, or payment demand.

Remove the source, not only the visible alert. Revoke notification permissions, inspect extensions and apps, and clear the offending site’s data.

Escalate when something consequential happened. Downloads, installations, remote access, credentials, identity information, and payments require a stronger response than merely seeing and closing a webpage.

Readers help support Windows Report. We may get a commission if you buy through our links. Tooltip Icon

Read our disclosure page to find out how can you help Windows Report sustain the editorial team. Read more

User forum

0 messages